HIGH

CVE-2020-13323

Gitlab GitLab 2020-09-30 CVSS v3.1
CVSS
7.7

Description

A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos

Summary dbcve.org

This is an information disclosure vulnerability in GitLab where private merge requests could be read through the Todos feature by unauthorized users. Under certain conditions, the access control intended to protect private merge requests could be bypassed, allowing users to view merge request details they should not have access to.

Mitigation

Upgrade GitLab to version 13.1 or later to remediate this vulnerability.

EPSS Score

1.1%
Probability of exploitation in next 30 days
64.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE